6.8.20

FBI warns of surge in online shopping scams

In one scheme, shoppers ordering gadgets or gym equipment are in for a rude surprise – they receive disposable face masks instead

 Amer Owaida

 The FBI’s Internet Crime Complaint Center (IC3) has recorded a surge in complaints from victims who have been duped by fraudulent online marketplaces that never deliver the purchased items.

According to the FBI, victims are reporting that they came across these fraudulent websites either through ads posted on social media platforms or while looking for specific items using popular web search engines’ shopping pages. The wares offered by the scammy online stores range from gym equipment to small appliances and furniture.

Oddly, regardless of what the victims ordered they received disposable face masks – a sort of twist on COVID-19 related schemes that have been doing the rounds for months now. Once the vendors receive complaints about the ordered items not being delivered, they offered partial reimbursement and the face masks as compensation.

Alternatively, the sellers requested the items to be returned to China; this spells outsize expenses for the victims, leading them to settle for the partial reimbursement and not having to return the items. However, none of the victims were able to get a full refund out of the miscreants.

In an attempt to make their deceptions more plausible, the faux retailers provide valid United States’ based addresses and telephone numbers in their “Contact us” sections. “Many of the websites used content copied from legitimate sites; in addition, the same unassociated addresses and telephone numbers were listed for multiple retailers,” the Bureau said.

The FBI shared several telltale signs of the websites being fake:

·       e prices were too good to be true,

·       tcybercriminals registered the web addresses within the last six months using private domain rregistration domain services to prevent their private information from being published,

·       iiinstead of using top-level domains like “.com”, the fraudulent websites instead used “.club” and “.top”,

·       tone site was promoted on social media.

To avoid falling for similar ruses, always do your due diligence on the retailer you’re considering purchasing from. Look into the reviews of the vendor, especially on third-party reviewing services. Use the contacts listed on their page to see if the information checks out and does belong to them. And always be vigilant, if an offer seems too good to be true, it usually is. For further advise on protecting yourself from various flavors of online scams you can refer to advice on fraud prevention shared recently by ESET Chief Security Evangelist Tony Anscombe.

Amer Owaida


30.7.20

FBI warns of disruptive DDoS amplification attacks



The Bureau expects cybercriminals to increasingly abuse new threat vectors for large-scale DDoS attacks

The Federal Bureau of Investigation (FBI) has issued an alert warning private sector organizations in the United States about a ramp-up in the use of built-in network protocols for large-scale distributed denial-of-service (DDoS) amplification attacks.
“A DDoS amplification attack occurs when an attacker sends a small number of requests to a server and the server responds with more numerous responses to the victim. Typically, the attacker spoofs the source Internet Protocol (IP) address to appear as if they are the victim, resulting in traffic that overwhelms victim resources,” wrote the FBI. The alert has been posted online, including on the website of the the New Jersey Cybersecurity and Communications Integration Cell (NJCCIC).
The FBI highlights recent threat vectors and developments, noting that the first DDoS amplification attacks to abuse the network protocols go back to December 2018, when cybercriminals exploited the multicast and command transmission features of the Constrained Application Protocol (CoAP). Most of the internet-accessible CoAP devices can be found in China and are using peer-to-peer networks.
During the summer of 2019, attackers took aim at the Web Services Dynamic Discovery (WS-DD) protocol to launch more than 130 DDoS attacks, some of which achieved a magnitude of 350 Gigabits per second. Internet of Things (IoT) devices use WS-DD protocols to automatically detect other devices nearby and since there are 630,000 with this protocol enabled, they can be attractive targets used to amplify DDoS attacks. That same year, researchers also reported a rise in the use of misconfigured IoT devices in amplified DDoS attacks.
In October 2019, miscreants abused the Apple Remote Management Service (ARMS), a part of the Apple Remote Desktop (ARD), to conduct DDoS amplification attacks. This protocol is usually employed by large organizations to manage their Apple computers.
Making matters worse, in February 2020 researchers found a vulnerability in the built-in network discovery protocols of Jenkins servers, which could potentially allow attackers to amplify DDoS attack traffic a hundredfold against their victims. There is no record of the flaw being exploited so far, but the FBI highlighted the resulting increase in the attack surface.
“In the near term, cyber actors likely will exploit the growing number of devices with built-in network protocols enabled by default to create large-scale botnets capable of facilitating devastating DDoS attacks,” said the FBI in its private industry notification.
The Bureau also outlined several steps to defend against the threat:
·       Set up a network firewall that will block access to all unauthorized IP addresses.
·       Ensure all your connected devices are updated to the newest firmware versions and have the newest security patches applied.
·       Change all the default usernames and passwords on your IoT and other devices and use two-factor authentication.
·       Register with a DDoS mitigation service.
DDoS attacks typically involve flooding a target with traffic that came from a large number of devices that have been corralled into a botnet, effectively bringing the victim’s services offline. These onslaughts are often unleashed as a way to extort money from the targets or even as a cover for other attacks. Whatever the motive, DDoS attacks in any of their flavors are known to cost organizations millions in lost revenue.

25.7.20

Dix conseils pour vous protéger contre les cybermenaces pendant vos vacances


Si vous faites partie de ces vacanciers qui ne partent jamais sans leurs appareils connectés, protégez-vous contre les cybermenaces avec ces quelques conseils.

Voici un guide pour vous permettre de voyager en toute sécurité et tout en gardant ainsi vos données personnelles et vos appareils protégés, que vous utilisiez un Wi-Fi public pour vous connecter à votre banque en ligne, une boutique en ligne ou tout simplement pour consulter vos e-mails pendant vos vacances.
1.     
Avant de prendre la route, assurez-vous d’exécuter sur vos appareils une mise à jour complète de votre système d’exploitation ainsi que des logiciels, et d’utiliser une solution de sécurité de confiance.
2.     
Sauvegardez vos données et conservez-les dans un endroit sûr. Pensez à déplacer les données sensibles du disque dur de votre ordinateur portable sur un disque dur externe chiffré le temps de vos vacances.
3.     
Ne laissez jamais vos appareils sans surveillance dans les lieux publics. Activez la fonction antivol de vos appareils pour tracer les appareils volés ou perdus, et au besoin d’effacer les contenus à distance.
4.     
Utilisez des mots de passe forts et uniques et activez la fonction « délai d’inactivité » sur tous vos appareils, que ce soit votre ordinateur portable, votre tablette ou votre téléphone. La vidéo suivante peut vous aider à choisir des mots de passe sécuritaires.
5.     
la mesure du possible, utilisez uniquement des accès internet de confiance. Demandez à votre hôtel ou l’endroit où vous logez le nom de leur Wi-Fi et ne vous connectez qu’au réseau ayant exactement le même nom : méfiez-vous des arnaques qui essaient de ressembler aux Wi-Fi publics en ajoutant le mot « gratuit » au nom de la connexion Wi-Fi.
6.     
l’Internet de votre hôtel vous demande de mettre à jour un logiciel afin de pouvoir vous connecter, déconnectez-vous immédiatement et informez-en la réception.

7.     Ne vous connectez pas à des connexions Wi-Fi qui ne sont pas chiffrées avec WPA2 ou WPA3
Tou
tes les normes inférieures à celle-ci ne sont tout simplement pas assez sûres et peuvent être facilement piratées.
8.     
Si vous devez utiliser le Wi-Fi public pour vous connecter à votre réseau d’entreprise, utilisez toujours votre VPN(réseau virtuel privé).
9.     
Si ce n’est pas urgent, évitez les banques et boutiques en ligne quand vous utilisez un Wi-Fi public. Sinon, nous vous conseillons d’utiliser le partage de connexion de votre téléphone et de surfer en utilisant internet sur votre téléphone portable.

10.  Utilisez toujours une solution de sécurité de confiance incluant un antivirus, y compris sur vos appareils mobiles tels que smartphones, tablettes, etc.

Mettre en application ces conseils vous permettra de partir en vacances l’esprit en paix. Vous pouvez maintenant fermez vos valises, et partir en toute tranquillité. N’oubliez pas votre brosse à dent et votre crème solaire!

Des commissaires à la vie privée demandent des vidéoconférences sécurisées



Une lettre ouverte souligne cinq principes de sécurité et de respect de la vie privée qui requièrent une attention accrue de la part des services de vidéoconférence.

Six autorités de protection des données et de la vie privée de pays de quatre continents ont adressé une lettre ouverte aux sociétés de vidéoconférence (VTC), leur demandant de réévaluer la manière dont elles protègent les droits à la vie privée et les données des citoyens dans le monde entier.

Puisque la pandémie nous a retenus dans nos maisons pendant la pandémie, les services de vidéoconférence ont connu une forte hausse de leur popularité, notamment pour rester en contact avec leurs amis et leur famille et pour organiser des réunions de travail, des cours en ligne et des rendez-vous médicaux virtuels. Toutefois, la hausse de la demande s’est également accompagnée de rapports soulignant les problèmes de sécurité rencontrés par certaines des plateformes, ainsi que de préoccupations directement exprimées auprès des organismes de réglementation eux-mêmes.

« Cette lettre ouverte a pour but d’exposer nos préoccupations, de clarifier nos attentes et les mesures que vous devriez prendre en tant qu’entreprises de services de vidéoconférence pour atténuer les risques soulevés et, en fin de compte, pour garantir que les renseignements personnels de nos citoyens sont protégés conformément aux attentes du public et à l’abri de tout préjudice.», explique la lettre, cosignée par les commissaires à la protection de la vie privée et les organismes de réglementation d’Australie, du Canada, de Gibraltar, de Hong Kong, de Suisse et du Royaume-Uni.

La lettre souligne cinq principes sur lesquels les sociétés de VTC devraient concentrer leur attention : la sécurité, le respect de la vie privée dès la conception, la connaissance de leur public, la transparence et l’équité, et le contrôle par l’utilisateur final. Elle s’adresse à l’ensemble des entreprises fournissant des services de vidéoconférence. Toutefois, Microsoft, Cisco, Zoom, House Party et Google ont reçu la lettre directement.

Les régulateurs attendent des entreprises qu’elles sécurisent les données des utilisateurs en mettant en œuvre certaines mesures de sécurité en standard, comme le chiffrement intégral de toutes les communications et l’authentification à deux facteurs pour les connexions, ainsi qu’en exigeant des utilisateurs qu’ils utilisent des mots de passe forts. Les plates-formes VTC doivent également inciter les utilisateurs à se mettre régulièrement à jour avec la dernière version de leur client de communication.

La lettre poursuit : « Il convient également de veiller tout particulièrement à ce que les renseignements soient correctement protégés lorsque des tiers les traitent, y compris dans d’autres pays. » Ses signataires reconnaissent également que la pandémie a conduit à une utilisation des plates-formes de CTV différente de celle pour laquelle elles ont été conçues, ce qui peut ouvrir la porte à des menaces imprévues. Ils encouragent les entreprises à examiner ces nouveaux cas d’utilisation et à mettre en œuvre les mesures nécessaires de protection des données et de la vie privée en conséquence.

Les commissionnaires soulignent également que « Cela revêt une importance particulière lorsqu’il s’agit d’enfants, de groupes vulnérables et de contextes où les discussions qui ont lieu sur les appels sont susceptibles d’être particulièrement sensibles (dans l’éducation et les soins de santé par exemple). C’est également le cas lorsqu’on mène des activités dans des territoires où les questions de droits de la personne et de libertés civiles pourraient créer un risque supplémentaire pour les personnes qui utilisent la plateforme. »

En ce qui concerne la transparence et l’équité, les entreprises sont invitées à être franches sur les données qu’elles collectent et la manière dont elles les traitent. La lettre poursuit en avertissant que tout manquement à cette obligation peut entraîner des violations de la loi et des abus de confiance de la part des utilisateurs. Les régulateurs de la vie privée s’attendent à recevoir des réponses des entreprises d’ici le 30 septembre 2020.

16.7.20

Details of 142 million MGM hotel guests selling for US$2,900




It appears that the July 2019 breach at MGM Resorts affected far more people than initially thought


The data breach at MGM Resorts that we also wrote about earlier this year may have been far larger than previously thought. In February, when the incident was disclosed, the estimated number of guests impacted by the breach was 10.6 million; however, now it seems that as many as 142 million hotel guests were affected by the incident that goes back to July 2019.

This is after ZDNet reported that a hacker had posted an add on a dark web criminal marketplace offering the personal data of more than 142 million former MGM Resorts guests for some US$2,900 worth of cryptocurrency.

A spokesperson for the hotel giant confirmed that the company knew about the size of the data breach. “MGM Resorts was aware of the scope of this previously reported incident from last summer and has already addressed the situation,” said the spokesperson, before adding that the majority of the leaked data consisted of mostly contact information, such as names, postal and email addresses.


The previous data dump contained a range of Personally Identifiable Information (PII), including full names, home addresses, phone numbers, emails, and birth dates. However, it did not appear to contain financial information or booking details, nor did it include any IDs or Social Security numbers. ZDNet was able to verify as much by reviewing the records from February, as well as a new batch of 20 million records that were released by the cybercriminals on Sunday. It also contacted past guests to confirm the veracity of the information.

It is worth noting that the leaked information could be enough for launching spearphishing campaigns or SIM swapping attacks. The victim list even includes a long list of potential high-profile targets, such as CEOs of tech companies, government officials, and celebrities.

In recent years, several other hotel operators – including InterContinental Hotels and the Trump Hotel Collection – have also fallen victim to similar incidents. Marriott Starwood suffered a data breach that affected a whopping 500 million guests.

Welkom Chat als een veilige berichten-app? Niets is verder van de waarheid verwijderd




ESET-onderzoek onthult een kwaadaardige operatie die zowel slachtoffers bespioneert als hun gegevens lekt


We ontdekten een nieuwe operatie binnen een langlopende cyberspionagecampagne in het Midden-Oosten. De operatie richt zich op Android-gebruikers via de kwaadaardige Welcome Chat-app en lijkt links te bevatten naar de malware genaamd BadPatch, die MITER linkt naar de Gaza Hackers-groep van bedreigingsactoren, ook wel bekend als Molerats .

Uit onze analyse blijkt dat de Welcome Chat-app het mogelijk maakt zijn slachtoffers te bespioneren. Het is echter geen simpele spyware. Welcome Chat is een functionerende chat-app die de beloofde functionaliteit levert, samen met zijn verborgen spionagecapaciteit.

We ontdekten dat deze spyware werd geadverteerd aan chat-hongerige gebruikers (deze apps zijn in sommige landen in het Midden-Oosten verboden) op een speciale website (zie figuur 1). Het feit dat de website in het Arabisch is, komt overeen met de targeting van de hele campagne waarvan wij denken dat deze operatie behoort. Het domein is geregistreerd in oktober 2019; we konden echter niet bepalen wanneer de website werd gelanceerd.

De kwaadaardige website promoot de Welcome Chat-app en beweert dat het een veilig chatplatform is dat beschikbaar is in de Google Play Store. Beide claims zijn onjuist. Met betrekking tot de "veilige" claim is niets minder waar. Welcome Chat is niet alleen een spionagetool; Bovendien lieten de operators de gegevens van hun slachtoffers vrij beschikbaar op het internet. En de app was nooit beschikbaar in de officiële Android-app store.



14.7.20

Zoom patches zero‑day flaw in Windows client



The vulnerability exposed Zoom users running Windows 7 or earlier OS versions to remote attacks

The Zoom videoconferencing platform was affected by a zero-day vulnerability that could have allowed attackers to execute commands remotely on affected machines. The flaw impacted devices running the Windows operating system, specifically Windows 7 and earlier.

The company has since addressed the issue and released a patch on Friday, with the release notes of version 5.1.3  (28656.0709) stating that the patch “fixes a security issue affecting users running Windows 7 and older.”

Technical details about are sparse about the vulnerability, which hasn’t been assigned a Common Vulnerabilities and Exposures (CVE) identifier and was first described by ACROS Security on its 0patch blog:
“The vulnerability allows a remote attacker to execute arbitrary code on victim’s computer where Zoom Client for Windows (any currently supported version) is installed by getting the user to perform some typical action such as opening a document file. No security warning is shown to the user in the course of an attack,” said ACROS.

However, the company also noted that the hole was “only exploitable on Windows 7 and older Windows systems”, as well as “likely also exploitable on Windows Server 2008 R2 and earlier”. By contrast, Windows 10 and Windows 8 are not affected.


ACROS was tipped off to the flaw by a researcher who wanted to remain anonymous. The company then ran an analysis of the researcher’s claims and tried out a number of attack scenarios before forwarding its findings to Zoom along with a proof of concept and recommendations on how to fix the issue. There is no word of attackers exploiting the bug in the wild.
ACROS also released a quick micropatch last Thursday that removed the vulnerability in the code before Zoom addressed the issue with a patch of their own. The micropatch was made available to everyone for free, with the company releasing a demonstration of how a user could easily trigger the vulnerability.